Trojan

How to remove “Trojan.Agent.DED”?

Malware Removal

The Trojan.Agent.DED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DED virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Lithuanian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Agent.DED?


File Info:

name: A8C5F51F635EFD324270.mlw
path: /opt/CAPEv2/storage/binaries/4acaa6fe29dc5f1c9ac1e9ad24615cb0b3a1bdac71f6a896da57b4bc1665c978
crc32: 61260434
md5: a8c5f51f635efd324270a7267434941a
sha1: 1224dac6a993c1d4c730582ef4f75cf34ff9f92c
sha256: 4acaa6fe29dc5f1c9ac1e9ad24615cb0b3a1bdac71f6a896da57b4bc1665c978
sha512: bb497c7a26808b665bed52c496648f62ba6458ea45480d315d2d374d8ee481a3e42765f360323296620ecc04e66caa81b8729e80fe4580e020744c627f51a06f
ssdeep: 6144:gc6pyZAhT1cACTfgjdlAhRSzbvB20g7yb/eK71xRMSWyTH1FJnrgS13FZ2B:gc6pj51kfgjdlACzd2NlKhxp31Dnrp1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D84F02236D0C132D9AB413469B79BF50B71BC344A38A29B77D47A7E5E307D0A62630F
sha3_384: c7e1122593d09e8734fee1628e6c20dff6c11e1ed494d6a2ee1fd58089383d969e8a47057e2ab82c3b606e56f310b3fa
ep_bytes: e8565e0000e978feffff558bec83ec08
timestamp: 2015-02-19 06:46:20

Version Info:

CompanyName: Create burn - www.Pain.com
FileDescription: Accident review swing
FileVersion: 2.0.0.2
Internal Name: Outline.exe
Legal Trademarks: Pain
Original Filename: Outline.exe
ProductName: Pain
ProductVersion: 1.0
LegalCopyright: Copyright (C) Pain 2006-2013
Translation: 0x0401 0x04b0

Trojan.Agent.DED also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.miet
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.24906
MicroWorld-eScanTrojan.GenericKD.2174452
FireEyeGeneric.mg.a8c5f51f635efd32
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.49541
SangforTrojan.Win32.GenericKD.2174452
K7AntiVirusTrojan ( 004c21261 )
AlibabaRansom:Win32/Foreign.e836248c
K7GWTrojan ( 004c21261 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.yq0@aOeeu6dk
VirITTrojan.Win32.Banker.AMT
CyrenW32/Trojan.FIWR-4351
SymantecPacked.Generic.521
ESET-NOD32Win32/Spy.Ursnif.AL
TrendMicro-HouseCallTSPY_ZBOT.AABBAC
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Foreign.lrrf
BitDefenderTrojan.GenericKD.2174452
NANO-AntivirusTrojan.Win32.RiskGen.efgrrz
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Sharik-K [Trj]
TencentWin32.Trojan.Foreign.Lpbh
Ad-AwareTrojan.GenericKD.2174452
EmsisoftTrojan.GenericKD.2174452 (B)
ComodoTrojWare.Win32.Yakes.ITS@5tots2
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.AABBAC
SophosML/PE-A + Troj/Wonton-OA
SentinelOneStatic AI – Malicious PE
JiangminTrojanProxy.Lethic.bz
eGambitUnsafe.AI_Score_99%
AviraTR/Rovnix.A.70
MAXmalware (ai score=86)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Heur.KVM007.a.(kcloud)
ArcabitTrojan.Generic.D212DF4
ZoneAlarmTrojan-Ransom.Win32.Foreign.lrrf
GDataWin32.Trojan.Agent.TZL23J
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R134933
Acronissuspicious
MalwarebytesTrojan.Agent.DED
APEXMalicious
RisingWorm.VBInjectEx!1.99E6 (CLOUD)
YandexTrojan.Foreign!up02T/oQ2nI
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.DBVZ!tr
WebrootTrojan.Dropper.Gen
AVGWin32:Sharik-K [Trj]
Cybereasonmalicious.f635ef
PandaTrj/Agent.IVN

How to remove Trojan.Agent.DED?

Trojan.Agent.DED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment